StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,296
of 17,803 indexed, latest versions
Container images
2,557
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,296 of 17,803 indexed charts deploy, on 2,557 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,656
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0898
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,296 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,557 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
hasura/graphql-engine:v2.34.0-ce0111b0204136
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
hasura/graphql-engine:v2.48.10f6c1c4b957d2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
haugene/transmission-openvpn:4.0059216cfae4b
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
haveagitgat/tdarr:2.00.181256348872ce
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hazegoodlife/haaze:milksite8d4c63169e14
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
headscale/headscale:0.25.1a7a8ae9616bb
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
headscale/headscale:0.27.1cd37b3001857
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
headwindmdm/hmdm:0.1.93550b4840840
openssl@3.0.2-0ubuntu1.26
no fix listed
1
heartexlabs/label-studio:latestaa461572e8f9
openssl@3.5.5-r0
3.5.6-r0
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
openssl@3.3.1-r3
3.3.7-r0
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
openssl@3.0.9-1
3.0.19-1~deb12u2
1
helmforge/fastmcp-server:0.2.061f759a1421f
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
hiboxsystems/marge-bot:0.16.0b59f01bc0418
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
1
hiversh/gateway:0.1.45839226cc6e41
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
openssl@3.0.9-1
3.0.19-1~deb12u2
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
openssl@3.0.9-1
3.0.19-1~deb12u2
1
hmediade/printserver:latest481a552c8e1c
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
1
hmediade/printserver-init:latest7f005eb6c718
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
openssl@3.3.3-r0
3.3.7-r0
1
housewrecker/gaps:latestf417dd0a7547
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
1
hugohg34/toposervice:0.0.2812a03b3f274
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
hyperglance/init:wildfly467ad8491bc3
openssl@3.0.2-0ubuntu1.23
no fix listed
1
hyperglance/init:postgres9fd5faf1fe80
openssl@3.0.2-0ubuntu1.23
no fix listed
1
hyperglance/init:apacheb2f8c6d52623
openssl@3.0.2-0ubuntu1.23
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
hyperledger/fabric-orderer:1.3.06ee1abcfd840
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
hyperledger/fabric-peer:1.3.06756c7c48234
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
openssl@1.0.2g-1ubuntu4.12
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/microclimate-theia:lateste17bdccc5030
nodejs@4.2.6~dfsg-1ubuntu4.1
openssl@1.0.2g-1ubuntu4.10
no fix listed
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/skydive:0.22.0395e60cc6e3d
openssl@1.1.0g-2ubuntu4.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
openssl@3.0.9-1
3.0.19-1~deb12u2
1
ilum/marquez-web:0.53.2716437a51a6c
openssl@3.5.4-r0
3.5.6-r0
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
infiniflow/infinity:v0.7.0992c87a68612
openssl@3.0.2-0ubuntu1.23
no fix listed
1
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
openssl@3.5.5-r0
3.5.6-r0
1
inseefrlab/shelly:cloudshell31f04ca7436b
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
instill/artifact-backend:b28766ac4a393e601ed
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
1
instill/console:0.68.54cd70e2df5c6
openssl@3.5.1-r0
3.5.6-r0
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.